Vulnerabilities > CVE-2011-1116 - Multiple Security vulnerability in Google Chrome

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
google
nessus

Summary

Google Chrome before 9.0.597.107 does not properly handle SVG animations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

Vulnerable Configurations

Part Description Count
Application
Google
1081

Nessus

NASL familyWindows
NASL idGOOGLE_CHROME_9_0_597_107.NASL
descriptionThe version of Google Chrome installed on the remote host is earlier than 9.0.597.107. Such versions are reportedly affected by multiple vulnerabilities : - An unspecified error exists in the URL bar operations which can allow spoofing attacks. (Issue #54262) - An unspecified error exists in the processing of JavaScript dialogs. (Issue #63732) - An unspecified error exists in the processing of CSS nodes which can leave stale pointers in memory. (Issue #68263) - An unspecified error exists in the processing of key frame rules which can leave stale pointers in memory. (Issue #68741) - An unspecified error exists in the processing of form controls which can lead to application crashes. (Issue #70078) - An unspecified error exists in the rendering of SVG animations and other SVG content which can leave stale pointers in memory. (Issue #70244, #71296) - An unspecified error exists in the processing of tables which can leave stale nodes behind. (Issue #71114) - An unspecified error exists in the processing of tables which can leave stale pointers in memory. (Issue #71115) - An unspecified error exists in the processing of XHTML which can leave stale nodes behind. (Issue #71386) - An unspecified error exists in the processing of textarea elements which can lead to application crashes. (Issue #71388) - An unspecified error exists in the processing of device orientation which can leave stale pointers in memory. (Issue #71595) - An unspecified error exists in WebGL which allows out-of-bounds memory accesses. (Issue #71717, #71960) - An integer overflow exists in the processing of textarea elements which can lead to application crashes. (Issue #71855) - An unspecified error exists which exposes internal extension functions. (Issue #72214) - A use-after-free error exists in the processing of blocked plugins. (Issue #72437) - An unspecified error exists in the processing of layouts which can leave stale pointers in memory. (Issue #73235)
last seen2020-06-01
modified2020-06-02
plugin id52501
published2011-03-02
reporterThis script is Copyright (C) 2011-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/52501
titleGoogle Chrome < 9.0.597.107 Multiple Vulnerabilities
code
#
# (C) Tenable Network Security, Inc.
#

include("compat.inc");

if (description)
{
  script_id(52501);
  script_version("1.15");
  script_cvs_date("Date: 2018/11/15 20:50:27");

  script_cve_id(
    "CVE-2011-1107",
    "CVE-2011-1108",
    "CVE-2011-1109",
    "CVE-2011-1110",
    "CVE-2011-1111",
    "CVE-2011-1112",
    "CVE-2011-1114",
    "CVE-2011-1115",
    "CVE-2011-1116",
    "CVE-2011-1117",
    "CVE-2011-1118",
    "CVE-2011-1119",
    "CVE-2011-1120",
    "CVE-2011-1121",
    "CVE-2011-1122",
    "CVE-2011-1123",
    "CVE-2011-1124",
    "CVE-2011-1125"
  );
  script_bugtraq_id(46614, 47020);
  script_xref(name:"Secunia", value:"43519");

  script_name(english:"Google Chrome < 9.0.597.107 Multiple Vulnerabilities");
  script_summary(english:"Checks version number of Google Chrome");

  script_set_attribute(attribute:"synopsis", value:
"The remote host contains a web browser that is affected by multiple
vulnerabilities.");

  script_set_attribute(attribute:"description", value:
"The version of Google Chrome installed on the remote host is earlier
than 9.0.597.107.  Such versions are reportedly affected by multiple
vulnerabilities :

  - An unspecified error exists in the URL bar operations
    which can allow spoofing attacks. (Issue #54262)

  - An unspecified error exists in the processing of
    JavaScript dialogs. (Issue #63732)

  - An unspecified error exists in the processing of CSS
    nodes which can leave stale pointers in memory.
    (Issue #68263)

  - An unspecified error exists in the processing of key
    frame rules which can leave stale pointers in memory.
    (Issue #68741)

  - An unspecified error exists in the processing of form
    controls which can lead to application crashes.
    (Issue #70078)

  - An unspecified error exists in the rendering of SVG
    animations and other SVG content which can leave stale
    pointers in memory. (Issue #70244, #71296)

  - An unspecified error exists in the processing of tables
    which can leave stale nodes behind. (Issue #71114)

  - An unspecified error exists in the processing of tables
    which can leave stale pointers in memory. (Issue #71115)

  - An unspecified error exists in the processing of XHTML
    which can leave stale nodes behind. (Issue #71386)

  - An unspecified error exists in the processing of
    textarea elements which can lead to application
    crashes. (Issue #71388)

  - An unspecified error exists in the processing of device
    orientation which can leave stale pointers in memory.
    (Issue #71595)

  - An unspecified error exists in WebGL which allows
    out-of-bounds memory accesses. (Issue #71717, #71960)

  - An integer overflow exists in the processing of
    textarea elements which can lead to application
    crashes. (Issue #71855)

  - An unspecified error exists which exposes internal
    extension functions. (Issue #72214)

  - A use-after-free error exists in the processing of
    blocked plugins. (Issue #72437)

  - An unspecified error exists in the processing of
    layouts which can leave stale pointers in memory.
    (Issue #73235)");

  script_set_attribute(attribute:"see_also", value:"http://www.nessus.org/u?3c074e5d");
  script_set_attribute(attribute:"solution", value:"Upgrade to Google Chrome 9.0.597.107 or later.");
  script_set_cvss_base_vector("CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C");
  script_set_cvss_temporal_vector("CVSS2#E:U/RL:OF/RC:C");
  script_set_attribute(attribute:"exploitability_ease", value:"No known exploits are available");
  script_set_attribute(attribute:"exploit_available", value:"false");

  script_set_attribute(attribute:"vuln_publication_date", value:"2011/02/28");
  script_set_attribute(attribute:"patch_publication_date", value:"2011/02/28");
  script_set_attribute(attribute:"plugin_publication_date", value:"2011/03/02");

  script_set_attribute(attribute:"plugin_type", value:"local");
  script_set_attribute(attribute:"cpe", value:"cpe:/a:google:chrome");
  script_end_attributes();

  script_category(ACT_GATHER_INFO);
  script_family(english:"Windows");

  script_copyright(english:"This script is Copyright (C) 2011-2018 Tenable Network Security, Inc.");

  script_dependencies("google_chrome_installed.nasl");
  script_require_keys("SMB/Google_Chrome/Installed");

  exit(0);
}

include("google_chrome_version.inc");

get_kb_item_or_exit("SMB/Google_Chrome/Installed");

installs = get_kb_list("SMB/Google_Chrome/*");
google_chrome_check_version(installs:installs, fix:'9.0.597.107', severity:SECURITY_HOLE);

Oval

accepted2014-04-07T04:00:57.091-04:00
classvulnerability
contributors
  • nameAharon Chernin
    organizationDTCC
  • nameShane Shaffer
    organizationG2, Inc.
  • nameShane Shaffer
    organizationG2, Inc.
  • nameShane Shaffer
    organizationG2, Inc.
  • nameMaria Kedovskaya
    organizationALTX-SOFT
  • nameMaria Kedovskaya
    organizationALTX-SOFT
  • nameMaria Mikhno
    organizationALTX-SOFT
definition_extensions
  • commentGoogle Chrome is installed
    ovaloval:org.mitre.oval:def:11914
  • commentGoogle Chrome is installed
    ovaloval:org.mitre.oval:def:11914
  • commentGoogle Chrome is installed
    ovaloval:org.mitre.oval:def:11914
  • commentGoogle Chrome is installed
    ovaloval:org.mitre.oval:def:11914
  • commentGoogle Chrome is installed
    ovaloval:org.mitre.oval:def:11914
  • commentGoogle Chrome is installed
    ovaloval:org.mitre.oval:def:11914
  • commentGoogle Chrome is installed
    ovaloval:org.mitre.oval:def:11914
  • commentGoogle Chrome is installed
    ovaloval:org.mitre.oval:def:11914
  • commentGoogle Chrome is installed
    ovaloval:org.mitre.oval:def:11914
  • commentGoogle Chrome is installed
    ovaloval:org.mitre.oval:def:11914
descriptionGoogle Chrome before 9.0.597.107 does not properly handle SVG animations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
familywindows
idoval:org.mitre.oval:def:14205
statusaccepted
submitted2011-12-09T10:38:40.000-05:00
titleGoogle Chrome before 9.0.597.107 does not properly handle SVG animations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
version52